ITAR Audit Preparation Checklist for Mid-Size Semiconductor Fabs
Most semiconductor fabs treat ITAR compliance like a fire drill — something you scramble for in the weeks before an audit. The problem is that ITAR violations don’t wait for audit season. A single unauthorized disclosure of controlled technical data can trigger penalties exceeding $1 million per violation, criminal referrals, and debarment from future defense contracts.
This checklist is designed for compliance managers at mid-size fabs ($50M–$500M revenue) who need a structured, repeatable framework for annual ITAR audits — without a 10-person export control team.
1. Registration and License Verification
Every U.S. manufacturer, exporter, or broker of defense articles must be registered with the Directorate of Defense Trade Controls (DDTC). Before your audit:
- Confirm active DDTC registration — verify your registration number and expiration date at pmddtc.state.gov
- Audit all active licenses — pull every DSP-5, DSP-73, and TAA currently in effect; verify end-user and end-use restrictions haven’t been breached
- Check license expiration dates — a lapsed license under which shipments continued is an automatic violation
- Confirm authorized end-users — compare shipment records against the approved end-users listed on each license
- Review any license conditions — some licenses carry reporting requirements (semi-annual, annual) that are frequently missed
Common gap: Fabs that grew through acquisition often inherit old licenses they didn’t apply for — and don’t realize they’re responsible for the compliance history attached to them.
2. Technical Data Controls
Under ITAR, “technical data” is broadly defined — it includes drawings, blueprints, process specifications, software source code, and even verbal conversations with foreign nationals about controlled technology.
- Identify all USML-controlled technology on your product line and map it to the correct U.S. Munitions List (USML) category
- Audit access controls on technical data repositories (SharePoint, PLM systems, engineering servers) — foreign nationals must be excluded without an approved license or DSP-5 authorization
- Review email and collaboration tools — Slack channels, Teams workspaces, and shared drives that contain ITAR data and include foreign national contractors or employees are a high-risk area
- Document your technical data identification process — auditors want to see a systematic methodology, not a one-time effort
- Confirm encryption standards for any controlled technical data transmitted electronically
Common gap: ITAR-controlled design files stored in cloud environments (AWS, Google Drive, Dropbox) where data residency and access permissions haven’t been formally assessed.
3. Employee Training Records
ITAR requires that all employees with access to controlled technical data receive training — and that you can prove it.
- Pull training completion records for all current employees with ITAR access — missing records are an immediate red flag
- Confirm training covered the current ITAR version — the regulations were significantly revised; training from 2019 or earlier may not satisfy current requirements
- Document new hire onboarding — every employee granted access since your last audit needs a training record
- Verify foreign national screening at time of hire and at access grant — this includes confirming citizenship status and checking denied party lists
- Check contractor and vendor training — third-party engineers on-site who touch controlled technical data are your responsibility
4. Denied Party Screening
Shipping or disclosing controlled data to a denied party — even unknowingly — is a violation.
- Confirm your screening tool is current — lists including the DDTC Debarred List, BIS Entity List, OFAC SDN List, and State Department Nonproliferation Sanctions are updated frequently
- Document screening frequency — auditors expect screening at transaction initiation, not just at onboarding
- Audit rescreening practices for long-running programs — a customer who was clean in 2022 may be listed today
- Check subsidiary and affiliate screening — export violations often involve shell companies; screen beneficial owners, not just the contracting entity
5. Recordkeeping and Evidence Packaging
ITAR requires you to maintain records of all exports, authorizations, and compliance activities for five years. During an audit, you’ll be asked to produce them on short notice.
- Locate all export documentation — shipping records, EEI filings, end-user certificates, and license copies for the past five years
- Confirm records are indexed and retrievable — auditors have limited time; if you can’t produce a record quickly, they assume it doesn’t exist
- Audit your electronic recordkeeping system — backups, access logs, and version history should be intact
- Prepare a compliance program summary — a one- to two-page document describing your ITAR compliance program, key personnel, and internal audit schedule gives auditors confidence before they start asking questions
6. Internal Audit and Self-Assessment
A robust ITAR compliance program includes annual internal audits before any external review.
- Conduct a mock audit using DDTC’s published guidelines and prior enforcement actions as a benchmark
- Document every finding — remediated gaps with evidence of correction are far better than undocumented issues an auditor finds first
- Assign a named compliance officer with documented authority and direct board or executive access
- Establish a violation reporting protocol — ITAR includes a voluntary disclosure program that typically results in significantly reduced penalties
The Bottom Line
ITAR audits reward preparation. Fabs that walk in with a clean, timestamped evidence package — organized by requirement, gap-free, and signed off by a named compliance officer — consistently fare better than those relying on tribal knowledge and last-minute document pulls.
AUDITPROOF maps your process records, supplier documentation, and export control filings against ITAR, EAR, and ISO requirements — and flags gaps before auditors do. Mid-size fabs using the platform go from months of scattered prep to a single-day evidence package.
Join the early access waitlist for the semiconductor compliance module →